The EU’s Cyber Resilience Act Comes into Force: Tech Firms Subject to a ‘Countdown’ System for Vulnerability Disclosure
2 hour ago / Read about 0 minute
Author:小编   

On September 11, 2026, the main provisions of the EU’s Cyber Resilience Act (CRA) officially came into effect. Under this act, manufacturers of digital products and software developers are mandated to report any security vulnerabilities in their products that could potentially be exploited by hackers to the EU’s cybersecurity agency within 24 hours. Moreover, they are required to provide remediation guidance to users within 72 hours. In addition, companies must establish a comprehensive safety management mechanism throughout the entire product lifecycle. Non-compliance with these regulations will result in substantial fines for companies, amounting to up to 2.5% of their global turnover or €15 million, whichever is higher.